Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 04 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash. The attack requires local access. A high complexity level is associated with this attack. The exploitation is known to be difficult. This patch is called 374945747652a8d32965591c0c01a00c88b7067f. Applying a patch is advised to resolve this issue. | |
| Title | PaddlePaddle FastDeploy MultimodalHasher hasher.py hash_features weak hash | |
| First Time appeared |
Paddlepaddle
Paddlepaddle fastdeploy |
|
| Weaknesses | CWE-327 CWE-328 |
|
| CPEs | cpe:2.3:a:paddlepaddle:fastdeploy:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Paddlepaddle
Paddlepaddle fastdeploy |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-04T15:07:01.551Z
Reserved: 2026-06-04T04:57:09.234Z
Link: CVE-2026-10800
Updated: 2026-06-04T13:38:59.139Z
Status : Deferred
Published: 2026-06-04T10:16:38.633
Modified: 2026-06-04T16:35:27.803
Link: CVE-2026-10800
No data.
OpenCVE Enrichment
Updated: 2026-06-05T10:08:23Z